WP-0001-T001: service scaffold (Python, FastAPI, uv, ruff, mypy, pytest)
Lands the smallest credible foundation per ADR-0005:
- pyproject.toml: hatchling build, runtime deps (FastAPI, uvicorn, SQLAlchemy 2.0,
asyncpg, aiosqlite, alembic, blake3, cbor2, typer, structlog, pydantic,
pydantic-settings); dev deps (pytest, pytest-asyncio, httpx, hypothesis, ruff,
mypy); ruff + mypy --strict + pytest configured.
- uv.lock committed.
- Makefile thin shims: install / dev / test / lint / format / type / migrate / clean.
- src/artifactstore/ package skeleton with placeholder __init__.py per concern:
identity, manifest, events, retention, audit, storage, dataplane, registry,
api/http (minimal FastAPI app, GET / scaffold banner), cli (typer app with
version subcommand), config (pydantic-settings).
- tests/{unit,integration}/conftest.py present; unit smoke tests assert package
imports, HTTP root route, CLI version round-trip, settings defaults.
- .env.example documents ARTIFACTSTORE_DATABASE_URL,
ARTIFACTSTORE_STORAGE_LOCAL_ROOT, ARTIFACTSTORE_LOG_LEVEL.
- README updated with install / dev / test instructions.
- .gitignore: claude local state, local runtime data (var/, sqlite db).
make lint && make type && make test pass on a clean checkout (4 tests, 20
source files type-clean under mypy --strict).
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-05-16 01:30:22 +02:00
|
|
|
[build-system]
|
|
|
|
|
requires = ["hatchling>=1.25"]
|
|
|
|
|
build-backend = "hatchling.build"
|
|
|
|
|
|
|
|
|
|
[project]
|
|
|
|
|
name = "artifactstore"
|
|
|
|
|
version = "0.1.0"
|
|
|
|
|
description = "Generic artifact registry and storage gateway"
|
|
|
|
|
readme = "README.md"
|
|
|
|
|
requires-python = ">=3.12"
|
|
|
|
|
license = { file = "LICENSE" }
|
|
|
|
|
authors = [{ name = "artifact-store contributors" }]
|
|
|
|
|
keywords = ["artifact", "storage", "registry", "evidence", "retention"]
|
|
|
|
|
classifiers = [
|
|
|
|
|
"Development Status :: 2 - Pre-Alpha",
|
|
|
|
|
"Intended Audience :: Developers",
|
|
|
|
|
"Operating System :: POSIX :: Linux",
|
|
|
|
|
"Programming Language :: Python :: 3.12",
|
|
|
|
|
"Programming Language :: Python :: 3.13",
|
|
|
|
|
"Topic :: Software Development :: Libraries",
|
|
|
|
|
"Topic :: System :: Archiving",
|
|
|
|
|
]
|
|
|
|
|
dependencies = [
|
|
|
|
|
"fastapi >= 0.115",
|
|
|
|
|
"uvicorn[standard] >= 0.30",
|
|
|
|
|
"sqlalchemy >= 2.0",
|
|
|
|
|
"asyncpg >= 0.29",
|
|
|
|
|
"aiosqlite >= 0.20",
|
|
|
|
|
"alembic >= 1.13",
|
|
|
|
|
"blake3 >= 0.4",
|
|
|
|
|
"cbor2 >= 5.6",
|
WP-0001-T010: manifest model, canonical CBOR codec, JCS projection
Adds the manifest layer per ADR-0003. The canonical wire format is CBOR with
deterministic encoding (cbor2 canonical=True: definite-length, shortest-form
integers, sorted map keys); JCS (RFC 8785) is the JSON projection.
src/artifactstore/manifest/:
- model.py: frozen dataclasses for Manifest (manifest_version=1, package,
files, storage_receipts, retention_summary, provenance) with restricted
types (str/int/bool/None/list/dict) so CBOR and JCS round-trip losslessly.
- codec.py: encode (Manifest -> canonical CBOR bytes) and decode (CBOR bytes
-> Manifest) via cbor2.
- projection.py: jcs_projection (Manifest -> RFC 8785 canonical JSON) plus
cbor_from_jcs for cross-format round-trip verification.
- digest.py: manifest_digest returns the BLAKE3 content address of the
manifest's canonical CBOR bytes (ADR-0001).
- __init__.py: re-exports the public surface.
tests/unit/test_manifest.py:
- decode(encode(m)) == m round-trip (hypothesis-parameterised).
- JCS↔CBOR round-trip: encode(decode(cbor_from_jcs(jcs(m)))) == encode(m).
- Byte stability of the canonical CBOR encoder across calls.
- manifest_digest matches independent BLAKE3 over encode(m).
- Decode rejects non-map CBOR.
- JCS projection sorts keys lexicographically.
Deps: jcs added to project requirements; mypy override for the jcs package
(no stubs published yet).
Gates: ruff clean, mypy --strict clean on 26 files, 26 tests pass.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-05-16 01:39:42 +02:00
|
|
|
"jcs >= 0.2",
|
WP-0001-T001: service scaffold (Python, FastAPI, uv, ruff, mypy, pytest)
Lands the smallest credible foundation per ADR-0005:
- pyproject.toml: hatchling build, runtime deps (FastAPI, uvicorn, SQLAlchemy 2.0,
asyncpg, aiosqlite, alembic, blake3, cbor2, typer, structlog, pydantic,
pydantic-settings); dev deps (pytest, pytest-asyncio, httpx, hypothesis, ruff,
mypy); ruff + mypy --strict + pytest configured.
- uv.lock committed.
- Makefile thin shims: install / dev / test / lint / format / type / migrate / clean.
- src/artifactstore/ package skeleton with placeholder __init__.py per concern:
identity, manifest, events, retention, audit, storage, dataplane, registry,
api/http (minimal FastAPI app, GET / scaffold banner), cli (typer app with
version subcommand), config (pydantic-settings).
- tests/{unit,integration}/conftest.py present; unit smoke tests assert package
imports, HTTP root route, CLI version round-trip, settings defaults.
- .env.example documents ARTIFACTSTORE_DATABASE_URL,
ARTIFACTSTORE_STORAGE_LOCAL_ROOT, ARTIFACTSTORE_LOG_LEVEL.
- README updated with install / dev / test instructions.
- .gitignore: claude local state, local runtime data (var/, sqlite db).
make lint && make type && make test pass on a clean checkout (4 tests, 20
source files type-clean under mypy --strict).
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-05-16 01:30:22 +02:00
|
|
|
"typer >= 0.12",
|
|
|
|
|
"structlog >= 24.1",
|
|
|
|
|
"pydantic >= 2.7",
|
|
|
|
|
"pydantic-settings >= 2.4",
|
|
|
|
|
]
|
|
|
|
|
|
|
|
|
|
[project.optional-dependencies]
|
|
|
|
|
dev = [
|
|
|
|
|
"pytest >= 8.0",
|
|
|
|
|
"pytest-asyncio >= 0.23",
|
|
|
|
|
"httpx >= 0.27",
|
|
|
|
|
"hypothesis >= 6.100",
|
|
|
|
|
"ruff >= 0.6",
|
|
|
|
|
"mypy >= 1.10",
|
|
|
|
|
]
|
|
|
|
|
|
|
|
|
|
[project.scripts]
|
|
|
|
|
artifactstore = "artifactstore.cli:app"
|
|
|
|
|
|
|
|
|
|
[tool.hatch.build.targets.wheel]
|
|
|
|
|
packages = ["src/artifactstore"]
|
|
|
|
|
|
|
|
|
|
[tool.uv]
|
|
|
|
|
dev-dependencies = [
|
|
|
|
|
"pytest >= 8.0",
|
|
|
|
|
"pytest-asyncio >= 0.23",
|
|
|
|
|
"httpx >= 0.27",
|
|
|
|
|
"hypothesis >= 6.100",
|
|
|
|
|
"ruff >= 0.6",
|
|
|
|
|
"mypy >= 1.10",
|
|
|
|
|
]
|
|
|
|
|
|
|
|
|
|
[tool.ruff]
|
|
|
|
|
target-version = "py312"
|
|
|
|
|
line-length = 100
|
|
|
|
|
src = ["src", "tests"]
|
|
|
|
|
extend-exclude = [".venv", "var", "migrations"]
|
|
|
|
|
|
|
|
|
|
[tool.ruff.lint]
|
|
|
|
|
select = ["E", "F", "W", "I", "N", "UP", "B", "C4", "RET", "SIM", "RUF"]
|
|
|
|
|
ignore = [
|
|
|
|
|
"B008", # FastAPI dependency injection idiom
|
|
|
|
|
]
|
|
|
|
|
|
|
|
|
|
[tool.ruff.lint.per-file-ignores]
|
|
|
|
|
"tests/**" = ["S101"]
|
|
|
|
|
"src/artifactstore/cli/__init__.py" = ["UP007"]
|
|
|
|
|
|
|
|
|
|
[tool.ruff.format]
|
|
|
|
|
quote-style = "double"
|
|
|
|
|
indent-style = "space"
|
|
|
|
|
|
|
|
|
|
[tool.mypy]
|
|
|
|
|
python_version = "3.12"
|
|
|
|
|
strict = true
|
|
|
|
|
files = ["src", "tests"]
|
|
|
|
|
mypy_path = "src"
|
|
|
|
|
explicit_package_bases = true
|
|
|
|
|
namespace_packages = true
|
|
|
|
|
|
WP-0001-T010: manifest model, canonical CBOR codec, JCS projection
Adds the manifest layer per ADR-0003. The canonical wire format is CBOR with
deterministic encoding (cbor2 canonical=True: definite-length, shortest-form
integers, sorted map keys); JCS (RFC 8785) is the JSON projection.
src/artifactstore/manifest/:
- model.py: frozen dataclasses for Manifest (manifest_version=1, package,
files, storage_receipts, retention_summary, provenance) with restricted
types (str/int/bool/None/list/dict) so CBOR and JCS round-trip losslessly.
- codec.py: encode (Manifest -> canonical CBOR bytes) and decode (CBOR bytes
-> Manifest) via cbor2.
- projection.py: jcs_projection (Manifest -> RFC 8785 canonical JSON) plus
cbor_from_jcs for cross-format round-trip verification.
- digest.py: manifest_digest returns the BLAKE3 content address of the
manifest's canonical CBOR bytes (ADR-0001).
- __init__.py: re-exports the public surface.
tests/unit/test_manifest.py:
- decode(encode(m)) == m round-trip (hypothesis-parameterised).
- JCS↔CBOR round-trip: encode(decode(cbor_from_jcs(jcs(m)))) == encode(m).
- Byte stability of the canonical CBOR encoder across calls.
- manifest_digest matches independent BLAKE3 over encode(m).
- Decode rejects non-map CBOR.
- JCS projection sorts keys lexicographically.
Deps: jcs added to project requirements; mypy override for the jcs package
(no stubs published yet).
Gates: ruff clean, mypy --strict clean on 26 files, 26 tests pass.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-05-16 01:39:42 +02:00
|
|
|
[[tool.mypy.overrides]]
|
|
|
|
|
module = ["jcs"]
|
|
|
|
|
ignore_missing_imports = true
|
|
|
|
|
|
WP-0001-T001: service scaffold (Python, FastAPI, uv, ruff, mypy, pytest)
Lands the smallest credible foundation per ADR-0005:
- pyproject.toml: hatchling build, runtime deps (FastAPI, uvicorn, SQLAlchemy 2.0,
asyncpg, aiosqlite, alembic, blake3, cbor2, typer, structlog, pydantic,
pydantic-settings); dev deps (pytest, pytest-asyncio, httpx, hypothesis, ruff,
mypy); ruff + mypy --strict + pytest configured.
- uv.lock committed.
- Makefile thin shims: install / dev / test / lint / format / type / migrate / clean.
- src/artifactstore/ package skeleton with placeholder __init__.py per concern:
identity, manifest, events, retention, audit, storage, dataplane, registry,
api/http (minimal FastAPI app, GET / scaffold banner), cli (typer app with
version subcommand), config (pydantic-settings).
- tests/{unit,integration}/conftest.py present; unit smoke tests assert package
imports, HTTP root route, CLI version round-trip, settings defaults.
- .env.example documents ARTIFACTSTORE_DATABASE_URL,
ARTIFACTSTORE_STORAGE_LOCAL_ROOT, ARTIFACTSTORE_LOG_LEVEL.
- README updated with install / dev / test instructions.
- .gitignore: claude local state, local runtime data (var/, sqlite db).
make lint && make type && make test pass on a clean checkout (4 tests, 20
source files type-clean under mypy --strict).
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-05-16 01:30:22 +02:00
|
|
|
[tool.pytest.ini_options]
|
|
|
|
|
asyncio_mode = "auto"
|
|
|
|
|
testpaths = ["tests"]
|
|
|
|
|
pythonpath = ["src"]
|
|
|
|
|
addopts = "-q --strict-markers"
|
|
|
|
|
markers = [
|
|
|
|
|
"integration: marks tests as integration (requires DB / backend)",
|
|
|
|
|
]
|